Data Governance Implementation Plan

This is a template document. All text in [square brackets] must be completed by your organisation. This template does not constitute legal advice. Review with your legal counsel before formal adoption.

1. Purpose

Plan the steps recommended by your AIRETT "Data Governance and Privacy" result. Pair this with the AI Governance and Acceptable Use Policy Template for the full policy text.

  • Organisation name: [Organisation name]
  • Data protection lead: [Name / role]
  • Data Governance score: [e.g. 4/15]

2. Implementation steps

StepOwnerTarget dateStatus
Classify organisational data by sensitivity level[ ][ ][ ]
Confirm/obtain DPAs for all AI vendors handling personal data[ ][ ][ ]
Publish internal prompt-hygiene guidance to staff[ ][ ][ ]
Define process for data-subject access/deletion requests involving AI tools[ ][ ][ ]
Complete a Data Protection Impact Assessment where required[ ][ ][ ]

3. Stakeholders to involve

[e.g. Data protection officer, IT, HR, any funder or partner with a data-sharing agreement]